CVE-2011-4182: shell code injection via ESSID because of missing escaping of a variable
Published Jun 12, 2018
·Updated
Missing escaping of ESSID values in sysconfig of SUSE Linux Enterprise allows attackers controlling an access point to cause execute arbitrary code. Affected releases are sysconfig prior to 0.83.7-2.1.
Affected Software
1 affected component
openSUSE Sysconfig<=0.83.7
Event History
Jun 12, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2011-4182?
The severity of CVE-2011-4182 is considered high due to the potential for attackers to execute arbitrary code.
2
How do I fix CVE-2011-4182?
To fix CVE-2011-4182, upgrade sysconfig to version 0.83.7-2.1 or later.
3
What versions are affected by CVE-2011-4182?
Affected versions of sysconfig for CVE-2011-4182 are those prior to 0.83.7-2.1.
4
Who is at risk for CVE-2011-4182?
Organizations using older versions of sysconfig on SUSE Linux Enterprise are at risk for CVE-2011-4182.
5
What type of vulnerability is CVE-2011-4182?
CVE-2011-4182 is a code execution vulnerability caused by missing escaping of ESSID values.